Sartia.by Exerevno ← Sartia

Applies to: the Sartia mobile app for iOS and Android

Privacy Policy

Effective Date: 4 August 2026  ·  Last Updated: 5 August 2026

1. Introduction and Scope

Exerevno Limited ("Exerevno", "we", "us", or "our") operates Sartia, a personal color analysis app for iOS and Android (the "App" or the "Service"). Sartia is built by Exer-labs, the product studio of Exerevno Limited.

This Privacy Policy explains what personal information the App collects, how we use and protect it, how long we keep it, and the rights you have in respect of it. It should be read alongside our Terms of Use.

The short version. Sartia analyses a photo of your face to work out your color season. Your photo is used only to create your result and is deleted within 24 hours (immediately after a successful analysis in normal operation), unless you turn on the optional retention setting. We never use your photo or your results to train AI models, and we never sell or share your personal information for advertising. We keep your color results, not your photo.

By using the App you acknowledge that you have read and understood this Privacy Policy. The analysis of your photo happens only after you give explicit, separate consent on the consent screen shown before your first analysis.

2. Who We Are and Our Role

Exerevno Limited acts as the data controller for personal information processed through Sartia. Our contact details are in Section 13.

3. Information We Collect

WhatWhy we collect itHow long we keep it
Your face photo To produce your personal color result. This is the only image we ever handle. Deleted within 24 hours by default, and immediately after a successful analysis in normal operation. Kept only if you turn on the optional retention setting, until you delete it or delete your account.
Onboarding quiz answers (style goal, color frustration, warm or cool confidence, self-reported natural hair and eye color, occasions, shopping frequency, age range) To personalise your analysis and guidance. Your self-reported hair and eye color feed the analysis. While your account is active. If you never create an account by purchasing, these are purged automatically 30 days after collection.
Email address captured at the end of the quiz, before any purchase To deliver your color profile and, only with your consent, to send you offers. Same as quiz answers: 30 days if you do not create an account, otherwise while your account is active.
Account email and sign-in identifiers (including your Google or Apple sign-in subject and session tokens) To create and secure your account and log you in. While your account is active.
Derived color measurements and your season result (skin, eye, and hair color values, undertone, contrast level, season, confidence) These are your saved report. They are non-image values and cannot be used to reconstruct your face. While your account is active.
Facial structure descriptors (Style+ subscribers only) To tailor style guidance to your features. We store qualitative descriptors only, never landmark coordinates or any template that could re-identify you. While your account is active.
Purchase and subscription records (amount, currency, status, store and RevenueCat identifiers, entitlement state) To unlock what you have paid for and to keep our financial records. While your account is active, and afterwards only where tax and accounting law requires, in minimal form.
An anonymous token generated by our server and stored on your device To tie your quiz, photo, and result together before you have an account. It is a random token, not a device fingerprint and not an advertising identifier. Until it is migrated to your account, or purged with the anonymous data at 30 days.
Operational and error logs To keep the Service working and diagnose faults. A short rolling window. Logs never contain your photo or any reversible biometric data.

3.1 What We Do Not Collect

4. Legal Bases for Processing (GDPR / UK GDPR)

For users in the EEA, UK, or Switzerland, we rely on the following legal bases:

Processing ActivityLegal Basis
Processing your face photo and deriving your color and facial structure results Explicit consent (Article 6(1)(a) and Article 9(2)(a)), given on the consent screen shown before your first analysis. No photo is captured or uploaded before you accept.
Collecting your email at the end of the quiz and sending you your color profile Consent (Article 6(1)(a)) given at the email capture screen, with the purpose stated on that screen.
Marketing email Consent (Article 6(1)(a)), recorded separately. Every message includes an unsubscribe link.
Creating and running your account, and delivering what you purchased Contract (Article 6(1)(b)).
Keeping financial and tax records Legal obligation (Article 6(1)(c)).
Securing the Service, rate limiting, and diagnosing faults Legitimate interests (Article 6(1)(f)): keeping the Service available, safe, and free from abuse.

Consent is granular and never pre-ticked. You can withdraw it at any time: turn photo retention off to delete a retained photo, unsubscribe from marketing email, or delete your account entirely (see Section 9 and our account deletion page). Withdrawing consent is as easy as giving it. If the consent text materially changes, we ask you to consent again before your next analysis.

5. The Photo Lifecycle

This is the part people most want to understand, so here it is in full:

  1. You accept the analysis consent screen. Nothing is captured before this.
  2. You take a selfie or choose a photo from your library.
  3. The App requests a single-use, short-lived upload link (valid for roughly 60 to 120 seconds) scoped to one file in a private storage bucket. The bucket is never publicly readable.
  4. Our server-side analysis function reads the photo, sends it to our vision model provider solely to produce your result, and writes back only non-image derived values (color measurements, season, confidence, and for Style+ subscribers, qualitative facial structure descriptors).
  5. The photo is deleted. In normal operation this happens immediately after a successful analysis, and a scheduled sweep guarantees removal within 24 hours for anything left behind.
  6. If you turned on the optional retention setting, the photo is kept on your account instead, so you can rerun or compare later, until you turn the setting off, delete the photo, or delete your account.

The only literal image we handle is transient. Everything we retain is a derived measurement that cannot reconstruct your face.

6. No Training, No Sale

7. Who We Share Information With

We share information only with the service providers listed below, each acting as a processor on our instructions, and where required by law.

ProviderPurposePrivacy Policy
Supabase Hosting, database, private photo storage, authentication, and the server-side functions that run the analysis supabase.com/privacy
Google LLC (Gemini API, paid tier) The vision model that analyses your photo to produce your result. Paid-tier content is not used to train Google's models. policies.google.com/privacy
RevenueCat, Inc. Subscription status and store receipt validation. No card data. revenuecat.com/privacy
Apple (App Store) and Google (Google Play) Payment processing, subscription billing, and app distribution. Your payment details are given to the store, never to us. apple.com/legal/privacy · policies.google.com/privacy

We may also disclose information if required by law, court order, or a governmental authority, or where we believe in good faith that disclosure is necessary to protect the rights, property, or safety of Exerevno Limited, our users, or the public. In the event of a merger, acquisition, or sale of all or substantially all of our assets, your information may be transferred to the successor entity, and we will notify you of any new privacy policy that applies.

8. Retention

9. Your Rights

We honour the strongest applicable standard across all our markets rather than running different flows per country.

We verify rights requests through your own signed-in session so that we act only on the account holder's request. We respond without undue delay and within one month, the strictest window that applies to us, extendable by two further months for complex requests under Article 12(3) GDPR.

You may also complain to your local supervisory authority: in the EEA see edpb.europa.eu, in the UK the Information Commissioner's Office (ico.org.uk), in New Zealand the Office of the Privacy Commissioner (privacy.org.nz), and in Australia the Office of the Australian Information Commissioner (oaic.gov.au).

10. International Data Transfers

Our processors operate outside some users' countries of residence, including in the United States. By using the App you acknowledge that your information may be transferred to and processed in jurisdictions with different data-protection laws than your own.

Transfers from the EEA, UK, or Switzerland: where personal data is transferred to a country without an adequacy decision, we rely on each provider's appropriate safeguards, including the European Commission's Standard Contractual Clauses (2021/914) and the UK International Data Transfer Addendum, as published by that provider.

Transfers from New Zealand: we comply with Information Privacy Principle 12 of the NZ Privacy Act, including by selecting providers whose terms ensure comparable safeguards.

11. Children

Sartia is for users aged 16 and over and is not directed to children under 16. You confirm your age when you accept the analysis consent screen. If we learn that we hold information from someone under 16, we delete it. If you believe a person under 16 has used the App, contact us at hyon.shim@exerevno.co.nz.

Sartia is for analysing your own appearance. Do not upload a photo of another person unless that person has agreed to be analysed. You are responsible for having that person's consent.

12. Security

No method of electronic transmission or storage is completely secure. While we strive to protect your information, we cannot guarantee absolute security. If a notifiable breach occurs we follow the applicable rules in each jurisdiction, including the NZ Privacy Act 2020 notifiable privacy breach scheme, the Australian Notifiable Data Breaches scheme, and the GDPR's 72-hour supervisory authority notification requirement.

13. Contact Us

For any question, concern, or request relating to this Privacy Policy or your personal information, please contact us:

Exerevno Limited
13/30 Upper Queen St, Auckland 1010, New Zealand
Email: hyon.shim@exerevno.co.nz
Website: www.exerevno.co.nz

14. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. When we do, we will revise the "Last Updated" date above and, where changes are material, take reasonable steps to notify you in the App. Where a change materially affects the consent you gave for photo analysis, we will ask you to consent again before your next analysis.